How to Use the Checkmarx MCP in LangChain
Build autonomous AppSec agents for Checkmarx with LangChain. This MCP Server connects your chains directly to your security scans.
Works with every AI agent you already use
…and any MCP-compatible client
Connect Checkmarx MCP to LangChain
Create your Vinkius account to connect Checkmarx to LangChain and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.
Chain Scans and Results
Start a workflow with `run_scan`. Your agent gets the scan ID, then polls `get_scan_details` until the scan is 'Completed'. It then passes that ID to `get_scan_results` to pull the vulnerability data. This creates a simple, effective CI/CD-style chain. You're not just running a scan; you're building a process that reacts to its own results. The output of one tool call becomes the input for the next, letting your agent work through a problem step-by-step without human intervention.
Pinpoint the Best Fix Location
Your agent can take a high-severity finding from `get_scan_results` and feed its details into `list_bfl`. This tool points to the exact file and lines of code for the most efficient fix. No more guesswork about where to start. It's a direct path from problem to solution. You can also build chains that specifically target infrastructure issues by calling `get_kics_results` to check your Terraform or Kubernetes configurations.
Manage Projects with Your LangChain MCP Server
Before kicking off any workflow, your agent can use `list_applications` and `list_projects` to get its bearings. It finds the right project ID and confirms the context before acting. This prevents it from scanning the wrong repository or branch. If a developer pushes a new commit mid-scan, a separate chain can trigger `cancel_scan` to avoid wasting resources on outdated code. This adds a layer of intelligence to your automation. It's a core benefit of using an MCP architecture.
Set up Checkmarx MCP in LangChain
Prerequisites
- Python 3.10+ installed
-
langchain-mcp-adapters+langgraphpackages - Active Vinkius subscription with a valid endpoint token
- 1
Install dependencies
Run
pip install langchain-mcp-adapters langgraph langchain-openai. The MCP adapters package converts MCP tools into native LangChainBaseToolobjects. - 2
Connect via HTTP transport
Use
MultiServerMCPClientwith"transport": "http"pointing to your Vinkius endpoint. Replace[YOUR_TOKEN_HERE]with your token from cloud.vinkius.com. - 3
Create a ReAct agent
Pass the discovered tools to
create_react_agent()from LangGraph. The agent automatically routes Checkmarx tool calls through the MCP protocol. - 4
Run with any LLM
Swap
ChatOpenAIforChatAnthropic,ChatGoogleGenerativeAI, or any LangChain-compatible model. The MCP tools work identically across all providers.
from langchain_mcp_adapters.client import MultiServerMCPClient
from langgraph.prebuilt import create_react_agent
from langchain_openai import ChatOpenAI
async with MultiServerMCPClient({
"checkmarx-mcp": {
"transport": "http",
"url": "https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp",
}
}) as client:
tools = client.get_tools()
agent = create_react_agent(
ChatOpenAI(model="gpt-4o"),
tools,
)
result = await agent.ainvoke({
"messages": "List recent Checkmarx transactions"
})
print(result["messages"][-1].content) Independent Platform Disclaimer: Vinkius is an independent platform and is not affiliated with, endorsed by, sponsored by, verified by, or otherwise authorized by Checkmarx. All third-party trademarks, logos, and brand names are the property of their respective owners. Their use on this website is strictly for informational purposes to identify service compatibility and interoperability.
Why Choose Vinkius
Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.
Real-time monitoring
Live
visibility into every interaction
Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.
Built-in savings
60%
lower AI costs
Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.
Single dashboard
One
place for every integration
Every tool your AI connects to, managed from a single screen. One account, complete control.
Common questions about Checkmarx MCP in LangChain
Use it with your favorite AI tools
Connect this server to Cursor, Claude, VS Code, and more.
Start using the Checkmarx MCP today
We host it, we monitor it, we maintain it. You just paste one token.